Privacy policy
Last updated: July 15, 2026
1. Who we are
PigeonDM (“the application”, “we”) is an automation tool that, with the authorization of the owner of a professional Instagram account, detects comments containing a keyword and automatically sends a private reply (direct message) through Meta’s official API.
Data controller: Antonin Langlade. Contact: info@pigeondm.com.
2. Data we process
When a comment is posted on a post of a connected account, we receive and process the following information through the Meta API:
- the content of the comment;
- the username and Instagram id of its author;
- the id of the post concerned;
- the time it was received.
We collect no passwords, no payment data and no private content beyond what is strictly necessary for the operation described here.
3. Purposes
This data is used only to:
- detect the keyword configured by the account owner;
- send the private reply (ref / link) to the author of the comment;
- keep a technical log of what was processed, for reliability and debugging.
4. Legal basis
Processing relies on the account owner’s legitimate interest in replying to their community, and on the implicit consent of the person who comments publicly with the explicit aim of getting the reply announced by the post.
5. Hosting and security
Supabase (PostgreSQL) holds the data; Vercel runs the application. The server reaches that database with a confidential service key that never leaves it, so no sensitive value ever reaches the browser. All traffic goes over HTTPS. We refuse any webhook that arrives without a valid X-Hub-Signature-256 signature, before reading a single field of it.
6. Who else sees this data
We never sell or rent it. It reaches only the providers the service cannot run without, each acting on our instructions and nothing more:
- Meta / Instagram sends us the comments and delivers the messages.
- Supabase (PostgreSQL) stores the accounts, the per-post configuration and the activity log.
- Vercel runs the application and its scheduled jobs.
- Inngest queues each incoming comment until it has been handled, so a comment is never lost when a send fails. The queued event carries the comment text and its author’s handle.
- PostHog (EU) records product usage. It receives the connected account’s Instagram user id and handle, so we can tell whether a connection succeeded. It never receives a message body, a commenter’s handle, or an access token.
7. How long we keep it
The activity log is deleted after 60 days, by a scheduled job in the database rather than on request. Four things outlive it on purpose. Your per-post configuration stays until you change or delete it, because it is what makes the service work. The record that a given person already received a DM for a given post is permanent, because it is the only thing that guarantees we never message anyone twice; it holds an Instagram user id and a post id, no message and no comment text.
And we keep daily totals of what the service did, one row per day: how many comments arrived, how many messages went out, how many failed. Those rows carry no account, no Instagram id and no text, so they describe the service and not you. That is what lets us answer “was June better than May” after the log itself is gone.
Finally, for your own account, we keep a daily count of your activity: how many comments your posts received, how many DMs went out, how many failed, one row per day. These carry no comment text and no third-party identity, so they describe your account’s volume rather than the people who commented. We keep them past the log so you can see your own trends beyond 60 days, and they are erased when you delete your account.
8. Your rights
Under the GDPR, you have a right of access, rectification, erasure, restriction and objection. To exercise it, write to us at info@pigeondm.com.
9. Deleting your data
Three ways, all of them immediate and none of them requiring us to do anything by hand:
- From the app. Settings → Delete my account. This erases the access token, your posts and keywords, and the whole activity log, at once and irreversibly, then hands you a confirmation code to keep.
- From Instagram, by removing the app. Settings → Apps and websites → PigeonDM → Remove. Instagram notifies us, and the access token is destroyed straight away, so nothing can be read or sent any more. Your configuration is kept for 30 days and then erased automatically. Reconnecting within that window cancels the deletion and keeps your setup.
- By asking Instagram to delete your data. Instagram sends us a signed deletion request; we erase everything immediately and return a link showing the status of your request, with a confirmation code.
We keep a receipt of each request, so we can show it was honoured. That receipt contains no Instagram username and no Instagram user id, only a one-way fingerprint that cannot be reversed back to an account.
Separately from any request, comment data is deleted automatically after 60 days. If you would rather write to a human: info@pigeondm.com.
10. Meta platform compliance
PigeonDM works through Meta’s official Instagram API, under the Meta Platform Terms and the Developer Policies. We use what that API returns for the purposes described above, and for nothing else. No resale, no advertising profiles, no training of models on your audience.
11. Changes
This policy may be updated; the date of the last update appears at the top of the page.
12. Contact
Antonin Langlade · info@pigeondm.com
